Description
Cross-site scripting (XSS) vulnerability in the CSS user subpage preview feature in MediaWiki before 1.23.15, 1.26.x before 1.26.4, and 1.27.x before 1.27.1 allows remote attackers to inject arbitrary web script or HTML via the edit box in Special:MyPage/common.css.
Remediation
References
Related Vulnerabilities
Oracle JRE CVE-2013-2433 Vulnerability (CVE-2013-2433)
MySQL CVE-2015-4772 Vulnerability (CVE-2015-4772)
Internet Information Services Other Vulnerability (CVE-2002-0149)
Apache Traffic Server CVE-2023-33933 Vulnerability (CVE-2023-33933)
TYPO3 Exposure of Sensitive Information to an Unauthorized Actor Vulnerability (CVE-2010-3673)